CVE-2019-8654: Apple Safari

Medium severity, CVSS 6.5. EPSS: 0.8% chance of exploitation in the next 30 days.

An inconsistent user interface issue was addressed with improved state management. This issue is fixed in Safari 13.0.1. Visiting a malicious website may lead to user interface spoofing.

Affected products

  • Apple Safari: before 13.0.1 (fixed in 13.0.1)

Published 2019-12-18. Last modified 2026-06-17.